Skip to content

Cyber Security And Bitcoin Blockchain News

The World

  • We’re Not Seeing Significant Macroeconomic Implications From Crypto Sell-Off – Regulation Bitcoin News bitcoin news
  • How Long Will The CryptoWinter Last? Cardano Founder Provides Answers bitcoin news
  • Bitcoin Records Worst Performance For June, Will It Get Better From Here? bitcoin news
  • Credibility Concerns — Gallop Poll Shows Fed Chair’s Confidence Ratings Slid by Double Digits – News Bitcoin News bitcoin news
  • With 12 Key Measures of Prices, Truflation’s Revamped Dashboard 2.0 Independently and Accurately Assesses Real-Time Inflation Rates bitcoin news
  • Blue Chip NFTs 101 – Let’s Travel To Space With The Doodles Collection bitcoin news
  • Buenos Aires’ “Crypto Building,” Innovation Or Marketing Ploy? Here’s The 411 bitcoin news
  • Biggest Movers:  SOL, NEAR, and AVAX Drop More Than 20% Lower on Wednesday – Market Updates Bitcoin News bitcoin news

New ‘Quantum’ Builder Lets Attackers Easily Create Malicious Windows Shortcuts

Posted on June 24, 2022 By root


A new malware tool that enables cybercriminal actors to build malicious Windows shortcut (.LNK) files has been spotted for sale on cybercrime forums.

Dubbed Quantum Lnk Builder, the software makes it possible to spoof any extension and choose from over 300 icons, not to mention support UAC and Windows SmartScreen bypass as well as “multiple payloads per .LNK” file. Also offered are capabilities to generate .HTA and disk image (.ISO) payloads.

Quantum Builder is available for lease at different price points: €189 a month, €355 for two months, €899 for six months, or as a one-off lifetime purchase for €1,500.

“.LNK files are shortcut files that reference other files, folders, or applications to open them,” Cyble researchers said in a report. “The [threat actor] leverages the .LNK files and drops malicious payloads using LOLBins [living-off-the-land binaries].”

Early evidence of malware samples using Quantum Builder in the wild is said to date back to May 24, masquerading as harmless-looking text files (“test.txt.lnk”).

“By default, Windows hides the .LNK extension, so if a file is named as file_name.txt.lnk, then only file_name.txt will be visible to the user even if the show file extension option is enabled,” the researchers said. “For such reasons, this might be an attractive option for TAs, using the .LNK files as a disguise or smokescreen.”

Launching the .LNK file executes PowerShell code that, in turn, runs a HTML application (“bdg.hta”) file hosted on Quantum’s website (“quantum-software[.]online”) using MSHTA, a legitimate Windows utility that’s used to run HTA files.

Quantum Builder is said to share ties with the North Korean-based Lazarus Group based on source code-level overlaps in the tool and the latter’s modus operandi of leveraging .LNK files for delivering further stage payloads, indicating its potential use by APT actors in their attacks.

CyberSecurity

The development comes as operators behind Bumblebee and Emotet are shifting to .LNK files as a conduit to trigger the infection chains following Microsoft’s decision to disable Visual Basic for Applications (VBA) macros by default across its products earlier this year.

Bumblebee, a replacement for BazarLoader malware first spotted in March, functions as a backdoor designed to give the attackers persistent access to compromised systems and a downloader for other malware, including Cobalt Strike and Sliver.

The malware’s capabilities have also made it a tool of choice for threat actors, with 413 incidents of Bumblebee infection reported in May 2022, up from 41 in April, according to Cyble.

“Bumblebee is a new and highly sophisticated malware loader that employs extensive evasive maneuvers and anti-analysis tricks, including complex anti-virtualization techniques,” the researchers said. “It is likely to become a popular tool for ransomware groups to deliver their payload.”





TheHackersNews/

cyber security news

Post navigation

Previous Post: Ethereum Key Indicators Suggest Strengthening Case For More Upsides
Next Post: Namibian University Set to Offer Master’s Degree in Blockchain Technology in 2024 – Bitcoin News

Related Posts

  • Chinese “Override Panda” Hackers Resurface With New Espionage Attacks cyber security news
  • Comprehensive, Easy Cybersecurity for Lean IT Security Teams Starts with XDR cyber security news
  • How to Improve Margins and Scale-Up Service Delivery cyber security news
  • Fake Clickjacking Bug Bounty Reports: The Key Facts cyber security news
  • Android and Chrome Users Can Soon Generate Virtual Credit Cards to Protect Real Ones cyber security news
  • Even the Most Advanced Threats Rely on Unpatched Systems cyber security news

Archives

  • July 2022
  • June 2022
  • May 2022

Categories

  • bitcoin news
  • cyber security news

Recent Posts

  • Russian Media Censor Roskomnadzor Blocks Major Crypto News Website – Bitcoin News
  • Jed McCaleb’s Ripple Stash Down to 81 Million — Co-Founder’s XRP Cache Likely to Dry Up This Year – Altcoins Bitcoin News
  • Exploit Forces Crema Finance to Temporarily Suspend Services, $8.7 Million Stolen – Bitcoin News
  • Blockfi CEO Says FTX Has an ‘Option to Acquire’ Crypto Lender at a Price of up to $240M – Bitcoin News
  • Dogecoin (DOGE) Could Use Some Lift

Recent Comments

No comments to show.
  • Hyperdex Launches Mainnet to Introduce Advanced Trading Features For DeFi Users bitcoin news
  • Bitcoin Bears Keep Pushing, Why BTC Could Still Nosedive bitcoin news
  • Bitcoin Perpetual Open Interest Suggests Short Squeeze Led To Crash bitcoin news
  • Crypto Losses? Koinly Reveals 5 Tax Hacks You Need Now – Press release Bitcoin News bitcoin news
  • Bitcoin Miner Liquidations Threaten Bitcoin’s Recovery bitcoin news
  • More Than 70% of Salvadorans Believe the Bitcoin Law Has Not Improved Their Personal Finances – Bitcoin News bitcoin news
  • Ethereum Bulls Keeps Pushing, Why ETH Could Rise Steadily bitcoin news
  • ‘Dr. Doom’ Nouriel Roubini to Launch Tokenized Dollar Replacement — With Payment and ESG Features – Bitcoin News bitcoin news

Copyright © 2022 Cyber Security And Bitcoin Blockchain News.

Powered by PressBook News Dark theme